---
id: CVE-2026-90934
title: >-
  EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in
  the meeting and call attendees endpoints that allows authenticated users to
  read restricted email addresses
summary: >-
  EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in
  the meeting and call attendees endpoints that allows authenticated users to
  read restricted email addresses. Attackers can recover hidden attendee emails
  by ex…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-863
vendor: espocrm
product: espocrm
affected:
  - espocrm < 10.0.4
published: '2026-09-14'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:47.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90934'
references:
  - url: 'https://github.com/espocrm/espocrm/security/advisories/GHSA-hpgx-8qg3-5w7v'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/espocrm-before-10.0.4-field-level-security-bypass-via-attendees
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00305
epssPercentile: 0.20727
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T17:32:41.138215Z'
ingestedAt: '2026-09-14T15:23:07.430Z'
---

## Overview

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by exploiting incorrect ACL scope validation that checks parent event permissions instead of attendee entity permissions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
